216.73.216.6

The Chrysalis Backdoor: A Deep Dive into Lotus Blossom's toolkit

· Published 03/02/2026 08:21 · Modified 03/02/2026 08:49

Export JSON

Essential information

Published
03/02/2026 08:21
Modified
03/02/2026 08:49
Tags
2026-02-03 apt backdoor china chrysalis cobalt strike metasploit notepad obfuscation warbird
Related entities
34 observables, 1 intrusion sets (apt), 3 malware, 7 others

Description

Rapid7 Labs has uncovered a sophisticated campaign attributed to the Chinese group Lotus Blossom, involving a new custom named . The attack compromised ++ infrastructure to deliver the . Analysis revealed multiple custom loaders, including one using Microsoft for . The has extensive capabilities for information gathering, file operations, and remote command execution. Additional artifacts found include beacons and payloads. The campaign shows Lotus Blossom evolving its tactics, mixing custom and off-the-shelf tools with advanced techniques to evade detection.

External references